Received: by 2002:a05:7412:37c9:b0:e2:908c:2ebd with SMTP id jz9csp2630448rdb; Fri, 22 Sep 2023 04:33:51 -0700 (PDT) X-Google-Smtp-Source: AGHT+IE/gRKV4QGp5iD7cOv1rgdcKKgYtY43Hq815WC4LE9qlBXBMCQyHMr2w8AdFa1jxJN1Ps1F X-Received: by 2002:a17:90a:414b:b0:274:60c7:e15a with SMTP id m11-20020a17090a414b00b0027460c7e15amr7471493pjg.4.1695382431568; Fri, 22 Sep 2023 04:33:51 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1695382431; cv=none; d=google.com; s=arc-20160816; b=rg6zSBuW6JBUMBu+BQj0b2UMYgbg7VVFOeKB6u4ke2NW3z7XN5OK1UiU4gcvyRso/l YsjChxdjNfb6P21kJJTsTbAysaBbgF1ZBRCyuoczK85qn9wj92eHvkqlk8UtYbVOamZM PBRdJAI46II5fFrYRABm2f8fDL+Ni+69u+50VEZLseZZOLJZPuuHgwppB5b6GNQtSK9L yHtOLiL1dABpw9xyc9rSfElbcoVGG3iWF/h0ML5ixX9Wpdol7bh6KAOPT8ZMB14IOa17 wg9eNpJTxoJWOnbOetbb4m2u7yTw7llaLPsOrrP7u3pbDM4j9j0vFaHiQjRr+x3r/64w tZ2Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=WFVgUoZXc2lZ26/cSu4xiqrrdHCsCggsCjjkAVBqrLs=; fh=KJoo3m47ZI7tUYPnaETYupdjJfRVCAl3xsaE/tC83+s=; b=lPoTZQpiHM2YoUV7sdehYYc1oa+3X6SbqDfgW/aQpJY3Pe7PUIdxgMay4YtHPqel0k 78UTw7BAgpbRRS3tm3PCE4u0SGm85sm8UzwVCGbVEeZRHlzCUfNRgQidSpQlNQzt7wJ+ /NVa0pGhg9qtKZlDjjmM+dIuJcgTahL8Q6nW+++R8wjWhDjZ9gh7DUBctUx8dWafdZpZ KzFhWKyqhpxlv/7QNSpUsuuwk1UwxjVPAhf/0tvslQXySVMcMIL4eMtEUELefYI1Esfl fsmU2wp1fIxEcc2LqOTR8tqOI5zdMNyB+2sDQNGfllBhZR4WvWZD1IDhNMfyE1Rw3kTG w2tA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@semihalf.com header.s=google header.b=RQBNfQbS; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=semihalf.com Return-Path: Received: from howler.vger.email (howler.vger.email. [23.128.96.34]) by mx.google.com with ESMTPS id cu9-20020a17090afa8900b002764d977cb8si3694433pjb.1.2023.09.22.04.33.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 22 Sep 2023 04:33:51 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) client-ip=23.128.96.34; Authentication-Results: mx.google.com; dkim=pass header.i=@semihalf.com header.s=google header.b=RQBNfQbS; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.34 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=QUARANTINE dis=NONE) header.from=semihalf.com Received: from out1.vger.email (depot.vger.email [IPv6:2620:137:e000::3:0]) by howler.vger.email (Postfix) with ESMTP id 5E3F280E2240; Thu, 21 Sep 2023 13:01:24 -0700 (PDT) X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.103.10 at howler.vger.email Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231397AbjIUUBU (ORCPT + 99 others); Thu, 21 Sep 2023 16:01:20 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:46582 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229884AbjIUUAw (ORCPT ); Thu, 21 Sep 2023 16:00:52 -0400 Received: from mail-lj1-x232.google.com (mail-lj1-x232.google.com [IPv6:2a00:1450:4864:20::232]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 4F45F6760C for ; Thu, 21 Sep 2023 10:30:12 -0700 (PDT) Received: by mail-lj1-x232.google.com with SMTP id 38308e7fff4ca-2b9c907bc68so20934451fa.2 for ; Thu, 21 Sep 2023 10:30:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=semihalf.com; s=google; t=1695317402; x=1695922202; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=WFVgUoZXc2lZ26/cSu4xiqrrdHCsCggsCjjkAVBqrLs=; b=RQBNfQbSoeR+FOsIo7kA3hfXblQiD1PSqpKe7uiKa6f8gQHhT0CnQ3ZuvKKg2Yrt/F 28uXqr05qZDzgE/V0OVryUceJ15tcjKcLiOkCxNRt3dqXtNKp/rtsV25a4uiEG9aeS/R 25lVLlaykaj9YBhssdx36sRbJfIcUfONbEq//mryGqayD/4q5hg+pTlkGTulPTLA6y83 m9aOs3N429KfHsKOX+lbp8W3AsLBvgDhkY1j+o4YBiZuyMAKaIAvJD8J/uFu70aSbxBd YA3RiOpDwHCgNfXAmoZOadWjJuGoLXsyycZBBljQj8kTj72gLRODBg+1bpUHT/lQDmvu zllA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1695317402; x=1695922202; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=WFVgUoZXc2lZ26/cSu4xiqrrdHCsCggsCjjkAVBqrLs=; b=CbErjyoVKsaBKI7VRFbYCLi9Ycn3O2ZeIvruP2D5fVQy+XZVJDGGXhWNf2Az5VU2Qg nJPDThdoyztYnwRVATs4UL99szrfrxvIaLYwyONqhV87sZNHTnseGw0mxC+uXZ+FwwlF Azm58KOLtzOmQ18FtfkgdV1Ij2lOZYFytH11f7ksBM+HeJvirIYqYKS4XkqdKOPm8uh3 Bbg+dR+3j2B61EafQNU2L/Jp22PpOIgJb0Nc0bDCm+nGbkc57OCthI1kVF9HfIiUx3lM jTA/mR6apzR/b1kiMBs5vUjIruzjxqyxcl8hE2Bl1FXUhCFvHnag6yeKLMUcXjzLNbGv lUGg== X-Gm-Message-State: AOJu0YwFUFkNNrPhuFHaQUo8NAjgtxFcsY5UjwhXmxmN/bQt5muYlTw7 MRebpYByyjm2EZ8xs9wvk8jUj6hqkIzsR6JdU2c= X-Received: by 2002:a2e:878d:0:b0:2bf:ec8e:97c9 with SMTP id n13-20020a2e878d000000b002bfec8e97c9mr4738193lji.17.1695302098400; Thu, 21 Sep 2023 06:14:58 -0700 (PDT) Received: from lmajczak1-l.roam.corp.google.com ([83.142.187.84]) by smtp.gmail.com with ESMTPSA id l20-20020a05651c10d400b002c01ff8442fsm337732ljn.130.2023.09.21.06.14.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 21 Sep 2023 06:14:57 -0700 (PDT) From: Lukasz Majczak To: David Airlie , Daniel Vetter Cc: Radoslaw Biernacki , Guenter Roeck , upstream@semihalf.com, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Lukasz Majczak , stable@vger.kernel.org Subject: [PATCH v2] drm/dp_mst: Fix NULL deref in get_mst_branch_device_by_guid_helper() Date: Thu, 21 Sep 2023 15:12:01 +0200 Message-ID: <20230921131201.157767-1-lma@semihalf.com> X-Mailer: git-send-email 2.42.0.515.g380fc7ccd1-goog MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_BLOCKED, SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4 (howler.vger.email [0.0.0.0]); Thu, 21 Sep 2023 13:01:25 -0700 (PDT) As drm_dp_get_mst_branch_device_by_guid() is called from drm_dp_get_mst_branch_device_by_guid(), we need to check mstb parameter, Check mstb parameter, otherwise NULL dereference may occur in the call to memcpy() and cause following: [12579.365869] BUG: kernel NULL pointer dereference, address: 0000000000000049 [12579.365878] #PF: supervisor read access in kernel mode [12579.365880] #PF: error_code(0x0000) - not-present page [12579.365882] PGD 0 P4D 0 [12579.365887] Oops: 0000 [#1] PREEMPT SMP NOPTI ... [12579.365895] Workqueue: events_long drm_dp_mst_up_req_work [12579.365899] RIP: 0010:memcmp+0xb/0x29 [12579.365921] Call Trace: [12579.365927] get_mst_branch_device_by_guid_helper+0x22/0x64 [12579.365930] drm_dp_mst_up_req_work+0x137/0x416 [12579.365933] process_one_work+0x1d0/0x419 [12579.365935] worker_thread+0x11a/0x289 [12579.365938] kthread+0x13e/0x14f [12579.365941] ? process_one_work+0x419/0x419 [12579.365943] ? kthread_blkcg+0x31/0x31 [12579.365946] ret_from_fork+0x1f/0x30 As get_mst_branch_device_by_guid_helper() is recursive, moving condition to the first line allow to remove a similar one for step over of NULL elements inside a loop. Fixes: 5e93b8208d3c ("drm/dp/mst: move GUID storage from mgr, port to only mst branch") Cc: # 4.14+ Signed-off-by: Lukasz Majczak --- drivers/gpu/drm/display/drm_dp_mst_topology.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/display/drm_dp_mst_topology.c b/drivers/gpu/drm/display/drm_dp_mst_topology.c index ed96cfcfa304..8c929ef72c72 100644 --- a/drivers/gpu/drm/display/drm_dp_mst_topology.c +++ b/drivers/gpu/drm/display/drm_dp_mst_topology.c @@ -2574,14 +2574,14 @@ static struct drm_dp_mst_branch *get_mst_branch_device_by_guid_helper( struct drm_dp_mst_branch *found_mstb; struct drm_dp_mst_port *port; + if (!mstb) + return NULL; + if (memcmp(mstb->guid, guid, 16) == 0) return mstb; list_for_each_entry(port, &mstb->ports, next) { - if (!port->mstb) - continue; - found_mstb = get_mst_branch_device_by_guid_helper(port->mstb, guid); if (found_mstb) -- 2.42.0.515.g380fc7ccd1-goog